Forced pip update raises supply chain safety concerns (and is often useless)
まだ誰も着手していません。
評価
- 難易度
- 5/5
- 見積もり時間
- 1週間以上
- 初心者へのやさしさ
- 35/100
- issue の種類
- 機能追加
- 明瞭さ
- おおむね明確
- 活発さ
- 静か
- 技術スタック
- github-actions, python, typescript
調査の方向性
ソースファイル、テスト、エントリーポイントは指定されていません。まず、setup-python の pip 自動更新パスと pip-version 入力の処理方法を追跡してください。完了条件は、呼び出し元がオプトアウトでき、最新バージョンへの無条件の更新を回避し、提案されたクールダウンを安全に適用できることです。
索引モデルが issue の本文から書いたものです。
説明
Description:
As of v6.3.0, setup-python appears to unconditionally auto-update pip, without a dependency cooldown.
Even when a pip-version input is specified, setup-python seemingly updates pip to the latest version first, then installs the specified version.
This behavior raises supply chain safety concerns: If pip itself were subject to a supply chain attack,[^1] any callers of setup-python would be immediately affected during the attack window of opportunity.
Also, updating pip on user level seems pointless when virtual environments are used (which you should), because (AFAIK) venvs are initialized with python's bootstrap copy of pip, not site-packages pip.
However, note that merely not calling setup-python's updated pip does not resolve these concerns, because an attacker might upload only an sdist of pip, which would allow for install-time execution of the hypothetical attack.
To be clear, we all hope that this scenario stays entirely hypothetical, but the point is that setup-python is not following safety best practices here, rsp. does not even allow the caller to do so.
Proposed remediation:
- Add an option to let the caller opt out of pip auto-updating entirely (given that it is pointless when a venv is used).
- Subject the default behavior of auto-updating pip to a dependency cooldown, ideally configurable through an input.
Suggested default: 3 days, like dependabot, or anything non-zero really. - When a
pip-versionis specified, install the given version right away without first updating to latest.
Note that updating pip itself with a cooldown is complicated by the fact that pip versions before 26 do not support --uploaded-prior-to, PIP_UPLOADED_PRIOR_TO etc.
This can basically be worked around by updating to a pinned and hash-checked version first, then updating with cooldown.
The following script shows how to do this: https://github.com/pypdfium2-team/pypdfium2/blob/811faae77f8fc90bc57832bc6400c65fd9f4fbee/utils/update_pip.py
Justification:
Supply chain safety, see the description above.
Are you willing able to submit a PR?
No, I am not a typescript programmer and not familiar with setup-python's internals.
Edit: Submitted https://github.com/actions/python-versions/pull/406 after all, a simple patch to avoid possible setup-time code execution when updating pip. This should stuff a key loophole and allow an aware caller to be unaffected, but otherwise the issue still stands.
[^1]: Hypothetical and hopefully highly unlikely, but no project is per se immune to it, and you have to acknowledge that pip would be a very lucrative target for a supply chain attack, so downstream precautions seem important.
- 主要言語
- TypeScript
- スター
- 2.2k
- フォーク
- 739
- 平均マージ
- 6日 18時間
- マージ済み PR(30日)
- 1
コントリビューションガイド
このリポジトリのコントリビューションガイドは索引されていません
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
actions/setup-python のほかの issue
-
bug
難易度 4/5 3〜5日 初心者へのやさしさ 55/100
actions/setup-python#1348 · コメント 5 件 ·
-
feature request
難易度 3/5 1〜2日 初心者へのやさしさ 58/100
actions/setup-python#1308 · コメント 8 件 ·
-
feature request
難易度 2/5 1〜3時間 初心者へのやさしさ 35/100
actions/setup-python#1301 · コメント 5 件 ·
-
feature request
難易度 4/5 3〜5日 初心者へのやさしさ 55/100
actions/setup-python#1294 · コメント 3 件 · リアクション 2 件 ·
-
feature request
難易度 2/5 1〜3時間 初心者へのやさしさ 20/100
actions/setup-python#1243 · コメント 2 件 ·
actions/setup-python の issue をすべて見る
似ている issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 65/100
-
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
-
bug v2
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
modelcontextprotocol/inspector#2458 · コメント 1 件 ·
-
難易度 1/5 1時間未満 初心者へのやさしさ 75/100
railmapgen/rmp-gallery#4068 ·
-
Mend: dependency security vulnerability status: needs triage 🕵️♀️
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
carbon-design-system/ibm-products#9907 ·